Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 41/126
7.2
CVE-2025-60787

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name

7.2
CVE-2025-47212

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack

7.2
CVE-2025-10239

In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privilege

7.2
CVE-2025-47856

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78]

7.2
CVE-2025-10242

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a

7.2
CVE-2025-10243

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a

7.2
CVE-2025-10985

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a

7.2
CVE-2025-5946

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Inf

7.2
CVE-2025-7850

A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

7.2
CVE-2025-8078

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, US

7.2
CVE-2025-6978

Diagnostics command injection vulnerability

7.2
CVE-2025-43941

Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('

7.2
CVE-2024-14008

Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizar

7.2
CVE-2025-34134

Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligenc

7.2
CVE-2025-34280

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management function

7.2
CVE-2025-34286

Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run C

7.2
CVE-2025-54763

FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user

7.2
CVE-2025-34239

Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.app

7.2
CVE-2025-64328 KEV

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and abov

7.2
CVE-2025-64444

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4

7.2
CVE-2025-34322

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimen

7.2
CVE-2025-58034 KEV

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul

7.2
CVE-2025-37163

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave

7.2
CVE-2025-66644 KEV

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2

7.2
CVE-2025-53679

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul

7.2
CVE-2025-53949

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul

7.2
CVE-2025-64153

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7

7.2
CVE-2025-65074

WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser

7.2
CVE-2025-67172

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_specia

7.2
CVE-2025-68459

RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injec

7.2
CVE-2023-53981

PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject maliciou

7.2
CVE-2025-13700

DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke

7.0
CVE-2024-48891

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in

6.8
CVE-2024-56137

MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large

6.8
CVE-2024-11681

A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running por

6.8
CVE-2024-57023

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" p

6.8
CVE-2024-57024

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute

6.8
CVE-2024-57025

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" p

6.8
CVE-2025-48204

The ns_backup extension through 13.0.0 for TYPO3 allows command injection.

6.8
CVE-2025-3705

A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of sp

6.8
CVE-2025-20319

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-priv

6.8
CVE-2025-43020

A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.

6.8
CVE-2025-8628

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8629

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8630

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8631

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8632

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8633

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8634

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8635

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started